CCC exploit drains $117K after attacker targets BSC liquidity pool
CCC token on BSC has suffered an exploit that caused an estimated $117,000 loss after an attacker manipulated the token contract's sell() function and burned tokens held in its liquidity pool.
Summary
- CCC suffered an estimated $117,000 exploit on BSC after an attacker targeted the token contract's sell() function.
- TenArmorAlert said the function was used to burn CCC tokens held in the liquidity pool, causing abnormal price movement.
- The security firm has not disclosed the full attack sequence or explained how the attacker was able to trigger the affected function.
- No detailed post mortem, fund recovery plan or compensation proposal had been announced at the time of the alert.
According to blockchain security firm TenArmorAlert, its monitoring system detected suspicious activity involving CCC on BSC on Aug. 28 and traced the incident to the token contract's sell() function. The firm said the function was used to burn CCC tokens directly from the liquidity provider pair, which was followed by abnormal movement in the token's price.
TenArmorAlert estimated losses from the attack at roughly $117,000. The firm identified an attack transaction beginning with "0x89d805064" in its security alert but did not provide a full breakdown of the assets removed or the attacker's final proceeds.
The available information does not identify how the attacker obtained the ability to trigger the affected function, whether access controls were bypassed, or whether another contract interaction was required before the tokens could be burned.
CCC exploit targeted tokens inside the liquidity pool
The reported attack centered on CCC tokens held by the LP pair instead of a direct withdrawal of assets from the pool.
TenArmorAlert said the contract's sell() function burned CCC from the LP pair. Removing tokens from a trading pair in this manner can alter the token balances used by the pool, though the security firm has not yet published a detailed technical analysis explaining the complete sequence of transactions in the CCC incident.
The firm specifically linked the activity to abnormal CCC price movement after the burn. Independent reports published after the alert carried the same estimated $117,000 loss and sell() function explanation.
No information available at the time of writing showed whether the CCC team had paused the affected contract, changed its permissions, recovered funds, or announced compensation for affected liquidity providers.
Details about the CCC token itself remain limited in the security alert. TenArmorAlert identified the affected network as BSC, commonly known as BNB Smart Chain, but its initial post did not name the decentralized exchange hosting the LP pair.
The mechanics described by TenArmorAlert bear similarities to previous token exploits in which contract functions were manipulated to change the balances of tokens held by liquidity pools.
BNB Chain has seen other contract exploits in recent months
The CCC incident follows several attacks involving token contracts and liquidity infrastructure on BNB Chain this year.
In July, crypto.news previously reported that Swan Treasury lost $625,000 after attackers obtained an off-chain signer key used by its ZhaiquanBuy contract. The compromised key allowed the attackers to generate valid signatures and buy STY tokens at a steep discount before selling them through a STY-USDT liquidity pool.
Blockchain security firm Defimon Alerts found that the Swan Treasury incident involved the contract's buy() function. The function calculated the amount of STY distributed based on a signed discount value, and the compromised signer allowed the attacker to generate signatures setting that parameter to one. The attacker could then obtain STY for about one-hundredth of its intended price.
Another BNB Chain-based token suffered a sharp price collapse in July after a separate exploit. Balance Coin fell more than 99% after security firms linked two suspicious transactions to an estimated $915,000 attack involving 42DAO.
TenArmor reported in that case that one transaction minted roughly 4.5 million unbacked BLC tokens before they were moved to PancakeSwap V2. The attacker reportedly exchanged the tokens for Binance-pegged USDT and BTCB, while BLC dropped from close to its intended $1 peg to an all-time low of $0.001209.
Liquidity pool attacks have used different contract weaknesses
Other attacks this year have reached liquidity pools through different contract-level weaknesses.
In June, Token of Power suffered a $1.58 million exploit involving its TOP/WETH Balancer V1 pool. Blockaid described the incident as a governance takeover attack, while Cyvers traced the loss to the affected Balancer pool.
The attacker drained 944.2 WETH from the pool, leaving it heavily diluted with TOP tokens. PeckShield later tracked 945.1 ETH sent to Tornado Cash. Security firms had not published a complete technical report on that attack at the time of the June report.
A May attack on DxSale involved another form of contract manipulation on BNB Chain. An attacker allegedly used a hidden contract backdoor to withdraw BNB locked by more than 1,400 liquidity providers, with losses estimated at $7.3 million. PeckShield later tracked about $1.87 million in BNB moving from an attacker-controlled address into two primary wallets before the assets were distributed to several Binance deposit addresses.
An older BNB Chain incident provides a closer technical comparison to the mechanism described in the CCC alert. SafeMoon lost about $8.9 million in March 2023 after an attacker exploited a public burn function that allowed tokens belonging to other addresses to be burned. The vulnerability had been introduced through a project upgrade and was used against the protocol's liquidity pool.
TenArmorAlert has not said whether the CCC sell() function contained a comparable permission flaw or whether the attack required a different sequence of contract calls. Its Aug. 28 alert only identified the function, the burn of CCC tokens from the LP pair, the resulting abnormal price behavior and the estimated $117,000 loss.
At the time of the alert, no detailed post-mortem, recovery plan or further information about the attacker had been disclosed.
-- Price
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.
You may also like

Circle expands CCTP to EURC and cirBTC on Arc

Bitcoin, Sports, and Politics: Predictive Markets Target $10 Trillion

AI Agent Jev Expects On-Chain Innovation Through Automated Judgment

The End of the Blank Prompt: Why Trading AI Needs a Playbook

Stablecoins hold nearly $200 billion in US debt, but money funds bought the surge
How Did a Hacker Create 46 Billion Fake Bitcoin in the Symbiosis Exploit? Decodes Bitcoin Hacker With WEEX Now
How two Symbiosis bridge bugs let a hacker mint 46.1 billion unbacked syBTC, drain Bitcoin pools and expose critical bridge risks.

CFTC's Selig Emphasizes the Need to Prepare for the Era of Large-Scale Tokenization in the U.S.

The IMF opens an office in Venezuela to supervise an economy that has already migrated to USDT

SOXL Stock Jumped 12% Yesterday: Three Companies Explain the Entire Move

Bitcoin's Hashrate Rises as Miners Reactivate Their Machines

Bitcoin 2x Leveraged ETF Launches on Cboe, But Doesn't Buy Bitcoin: Here's Why

Crypto: The ECB Enters the Tokenized Bond Market
WEEX Bitcoin Weekly Outlook: Why Did Bitcoin Rebound Above $80,000 After the CLARITY Act Vote?
Bitcoin rebounded above $80,000 as SEC and CFTC action, renewed ETF inflows, and a short squeeze outweighed the failed CLARITY Act vote.

Coldcard whitehats move 52.37 BTC to recovery trust

Bitcoin's Rise Does Not Mean the Bull Market Has Returned; Don't Create Stories for Yourself

Deutsche Bank: Markets May Underestimate Rate Peaks After Central Banks' Coordinated Rate Hikes

Hyperliquid Opens Market for Bitcoin Volatility

Tom Lee Discusses Entry into Digital Asset Bull Market and AI Fund Movements

Micron Stock Price Target: Do the $1,500 to $2,000 Estimates Still Make Sense
Micron price targets range from $1,295 consensus to $1,500- lus individual calls, while options pricing implies an 11% swing on September 30 earnings, the actual results will settle which
![[ETH Letter] Ethereum Aims to Activate Sepolia Testnet on October 6](/public-static/26_2e1840f602.png?format=avif)
[ETH Letter] Ethereum Aims to Activate Sepolia Testnet on October 6

Fypher Partners with Korea Medical Tourism Promotion Association for Digital Dollar Payment

TapeOut Ecosystem Overview: From NAND, LATCH to On-Chain Application Ecosystem
![[Coin Crime] "If you give us Tether, we will give you oil" - Polish state-owned company falls victim to international fraudsters](/public-static/18_26310349ce.png?format=avif)
[Coin Crime] "If you give us Tether, we will give you oil" - Polish state-owned company falls victim to international fraudsters

Why real-time election odds are misleading prediction market crypto traders

What is PCE and Why September 30 is Important for Cryptocurrencies

Bitcoin: JPMorgan Sees BTC Outperforming Gold

U.S. Treasury Sanctions BitBank Over Iranian Sanctions-Evasion Network

Brazil blocks stablecoins from key cross-border payment rail as $1.1 trillion market faces new limits

RISEx Proposes 20% Retention Condition for Stolen Funds

USDT in Wallets May Be Blocked. What to Do and How to Store Them in Russia
Circle expands CCTP to EURC and cirBTC on Arc
Bitcoin, Sports, and Politics: Predictive Markets Target $10 Trillion
AI Agent Jev Expects On-Chain Innovation Through Automated Judgment
The End of the Blank Prompt: Why Trading AI Needs a Playbook
Stablecoins hold nearly $200 billion in US debt, but money funds bought the surge
How Did a Hacker Create 46 Billion Fake Bitcoin in the Symbiosis Exploit? Decodes Bitcoin Hacker With WEEX Now
How two Symbiosis bridge bugs let a hacker mint 46.1 billion unbacked syBTC, drain Bitcoin pools and expose critical bridge risks.









